Presentation is loading. Please wait.

Presentation is loading. Please wait.

Some basics of a AAA Control model

Similar presentations


Presentation on theme: "Some basics of a AAA Control model"— Presentation transcript:

1 Some basics of a AAA Control model
John Vollbrecht Merit Network March 30, 2000 Adelaide ietf

2 AAA Elements and relationships
Authentication Server user Authorization Server Application Simple model – single domain/kingdom

3 Certificate/Token Sequence
1 Authentication Server 2 User agent Authorization Server 3 Application 1- get authentication token 2 – get authorization token 3- initiate application

4 Net Access Sequence an example
Authentication Server 3 4 Authorization Server User Agent 2 5 1 Edge Device 6 1 –request service/ with userinfo 2 – forward request with userinfo 3 – forward request with userinfo 4 – return authentication token 5 – return authorization token return session start

5 Bandwidth Broker an example
1 Authentication Server 2 3 User agent Authorization Server 4 6 5 Bandwidth Broker 1,2 – get authentication token request QoS Bandwidth authorized QoS request 5 – Session start – forward Session start

6 Some issues Which party controls the request sequence
Security requirements between parties in different sequences Possible onetime authorization or authentication Complexity of issues as multiple organizations get involved in Authentication or Authorization or resource/application provisioning

7 Some Goals One goal is a descriptive model that provides a basis for understanding what is common and what is unique between application domains Attempt to support Policy descriptions of sequences of AAA actions for specific application domains Provide a way to evaluate policy from multiple organizations for a specific request.


Download ppt "Some basics of a AAA Control model"

Similar presentations


Ads by Google